Mexico’s misinformation wars :

How organized troll networks attack and harass journalists and activists in Mexico

Amnesty Global Insights
Amnesty Insights
Published in
10 min readJan 24, 2017


By Tanya O’Carroll, Adviser on Technology and Human Rights (@TanyaOCarroll). Interview with Alberto Escorcia (@LoQueSigue_). With investigations by Daniel Santos.

It´s a bright winter day and we´re seated at the plastic tables in a coffee shop in downtown Mexico City, Alberto´s choice of venue. He hunches over a laptop as he animatedly talks me through a short history of what he calls “techno-censorship” in Mexico. It´s hard to keep up as he shifts rapidly between webpages. Each is indexed clearly in his memory: “you see, I´m quite obsessive Tanya”.

What he calls obsession could also be called a propensity for detail and a great deal of patience. Both are prerequisites when your line of work is documenting the thousands of abusive tweets that collectively make up the daily activity of Mexico´s orchestrated troll networks.

Alberto Escorcia, Ciudad de México

“It´s a huge problem in Mexico”, Alberto tells me. “On an average day, I see two or three trending topics generated by the trolls. Anywhere between 1000 and 3000 tweets a day. Many operate as part of organized “troll gangs” who are paid to make stories go viral or to launch campaigns discrediting and attacking journalists.”

The techno-censorship Alberto witnesses online is simply the latest frontline in a hidden war that aims to silence journalists and those who speak out.

“If they don´t kill you, they ruin your life. The trolls generate a constant climate of fear, and it stops people from publishing”.

Alberto speaks from experience. Since becoming a thorn in the side of the trolls, he has faced mounting harassment and death threats.

For example, in September this year, trolls launched a vicious spate of death threats targeting journalists and human rights groups on the second year anniversary of Ayotzinapa, the date that 43 students were forcibly disappeared in Mexico.

Using the phrase “él patrón ya dio la orden” (the boss has given the order) the troll accounts posted threatening tweets, such as this one sent to Centro Prodh, a leading human rights organization in Mexico. It warned its staff not to attend the Ayotzinapa protests unless they wanted “their blood spilt”.

Tweet reads: Hello @CentroProdh I hope you don´t go to the Angel (meeting spot) at 4pm, that´s if you don´t want your blood spilt. The boss has given the order.

Alberto documented the attacks and reported the accounts behind them to Twitter. While the @TercoDJesus account was blocked, others popped up. This time Alberto became their target.

Tweet reads: Son of a b**** @AlbertoEscorcia the boss has seen your article where you say bad things about him, say goodbye to your family, you´re a dead man.
Tweet reads: @AlbertoEscorcia You’re living up to your username f***ing journalistic scum the boss has given the order @xxElNoruegoxxx (Escorcia sounds like escoria, meaning scum in Spanish)

Amnesty downloaded and analysed all of the tweets using “Él patrón ya dio la orden” and found 2377 accounts tweeting on the hashtag. In the spate of just two days, at least 10 journalists, public figures and human rights groups received violent death threats bearing the same hallmarks.

The troll takeover of Twitter in Mexico

What is happening online is nothing more than a reflection of what is happening offline in Mexico.

“Since the war on drugs began in 2006, we´ve lived through the worst period for freedom of expression”, says Alberto.

Mexico is one of the most dangerous countries on earth to be a journalist, according to the Committee to Protect Journalists. It is also in the middle of a human rights crisis, stained by the disappearance of almost 30,000 men, women and children over the last decade — most since the current President, Peña Nieto took office in 2012.

The violence — and the impunity shrouding it — has energized a new generation of digitally-savvy Mexican activists who want to see accountability for the human rights abuses committed.

Alberto is one of them. In 2012, he became active in the #YoSoy132 student movement, initiated in protest against Mexico´s political elites during the presidential campaign that year. Using an online pseudonym, Alberto called for some of the protests and quickly became adept at analyzing social media data in order to be able to organize more effectively. That´s when he started to notice a dark new presence on social media:

“At first their tactics were unsophisticated. They were basically spambots that would flood Twitter with thousands of automated tweets. They were a nuisance, hijacking hashtags we were using to organize protests and filling them with spam and false information.”

The spambots were relatively easy for Twitter to block. By adjusting their algorithm they could detect when hundreds of tweets with the exact same message were posted within a split second, and automatically mark it as “spam”.

But the tactics soon evolved. Instead of automated bots, real people started to operate the accounts, making it hard for Twitter to differentiate between spambots and real users.

And where there is demand, there is a market. Alberto believes there is now a whole commercial sector underpinning the trolls, in which people are paid to spread misinformation and abuse online.

“They´ve not really got a political agenda. They could mobilize for any cause they´re paid for. I´ve seen them organize to promote the government´s new energy reform bill and to lobby against a proposed sugar tax. The next day they could be working together to make a death threat go viral”.

It´s not easy to prove. One of the trolls´ hallmarks is how opaque and difficult to investigate they are. Like a black hole, we can see the activity surrounding them but in the centre remains a big question mark. How many people are behind the accounts? How are they organized?

The little Alberto knows is thanks to a repentant troll operator who approached him in 2014 out of guilt. She confessed to having been paid 50,000 pesos an hour (almost USD $2,500) to run up to 150 accounts against Mexico´s #YaMeCanse protests, which swept the country in the wake of the disappearance of the 43 Ayotzinapa students (YaMeCanse means “I’ve had enough” in Spanish).

The orange smudge at the top is the start of the troll offensive against #YaMeCanse. The protesters had to change to #YaMeCanse2, and then 3, all the way to 33, in order to stay ahead of the trolls who flooded the hashtag with spam.

Twitter themselves admit that they face a particularly nasty problem in Mexico. The company´s policy team describe it as an endless game of techno one-upmanship. The trolls evolve their tactics and Twitter´s spam team evolve theirs. However, Twitter are reluctant to block accounts that could belong to people expressing genuine views.

However, a bigger problem seems to be one of resourcing on Twitter´s Spam team. Their response to policing abuse in Spanish is patchy at best. Sometimes they block the trolls quickly, other times it takes days, and requires chasing. Other times, Alberto simply receives a message saying that the account was not found to have violated Twitter’s Rules (in cases where tweets were quite clearly abusive). Later, they may decide to suspend or block the account after all. When querying Twitter about why and how such decisions are made, the answers are not forthcoming. Meanwhile, without effective action from Twitter, the troll networks keep multiplying.

Which is why Alberto now spends hours each day documenting the trolls. He hopes that with enough evidence, Twitter can be persuaded to properly investigate the troll takeover of their platform in Mexico and devise more effective strategies to combat the abuse.

At the moment, it´s a futile game of Whac-a-Mole. Each time Alberto successfully reports an account and Twitter blocks it, another one opens immediately with a new name. Alberto can’t keep up.

From death threats to defamation campaigns

Alberto browses through a list of Twitter hashtags to show me another example. He picks a Twitter trending topic from two weeks earlier: #LosSecretosdeAristegui (the secrets of Aristegui).

Carmen Aristegui is one of Mexico´s most renowned investigative journalists, something she has paid a heavy price for. She was fired twice from national radio and now faces a civil lawsuit alleging defamation for an investigation she ran, back in late 2014, into the acquisition of President Peña Nieto’s house. Most recently, on 13 November 2016, her office was broken into and a laptop taken.

In addition to these traditional tactics of repression, in the past few years Aristegui has come under fire from a new kind of threat: massive, coordinated troll attacks that focus on intimidating and discrediting her.

#LosSecretosdeAristegui was launched on 16 November following the release of a video on Facebook accusing the journalist of taking money from Mexican telecom magnate, Carlos Slim. The video was posted by an account called ElPueblo Informa, which appears to have been set-up with this purpose alone (the account had no other published content when we checked it). Troll networks then launched their offensive on Twitter, soon turning the hashtag into a trending topic.

“They are not limited to Twitter, they depend on a whole ecosystem of fake sites and blogs in Mexico”, Alberto tells me. “That´s how they seed false stories and create trending topics out of them”.

Sat in the cafe, Alberto downloads 5,109 of the tweets associated with the hashtag #LosSecretosdeAristegui and uses a programme called Gephi to analyse patterns. Gephi works by identifying groups within the network than are closely coordinated (usually because they retweet or mention each other). Trolls are distinguishable because they usually have tight follow networks (they all follow each other), and often follow fewer accounts than real users. Once he has identified a network, Alberto then examines a few of the accounts and individual tweets, in order to confirm they are trolls.

A screenshot of Alberto´s laptop showing #LosSecretosdeAristegui visualized on Gephi — there are four networks active on the hashtag. Carmen Aristegui´s supporters are visible in green. The black cluster is the same abusive troll network that launched the death threats against activists and journalists #ElPatronYaDiolaOrden

Among the various clusters that are visible on the hashtag, Alberto recognizes a group of trolls who call themselves the Holk Legion (the black cluster above). The Holk Legion openly take credit for launching abusive hashtags in Mexico, and they have targeted Aristegui in the past. An account that claims to be an admin of the Holk Legion — @LeHolker2 — called for help turning #LosSecretosdeAristegui into a Trending Topic (the original tweet has now been deleted but the retweets are still visible).

Tweets read: “#LosSecretosdeAristegui is active” and “#LosSecretosdeAristegui here we go again”

Other accounts joined in, sending Carmen Aristegui death threats in the same style as the spate of attacks on La Patrón Ya Dio La Orden.

Tweet reads: Read carefully Miss Carmen now we have what we want you are no use to us anymore. The attached image is a note covered in bullets which says “you have f***ing had it”

Since she was fired from the national radio, Carmen Arigestui has run an independent news portal online. I spoke to her team who estimated that each large orchestrated troll attack diminishes their capacity by 20–50%, as staff are occupied with responding to the attack. In their words:

“When we are small teams, the fact that one hand is dedicated to this, distracted by dealing with the attacks, we lose quality in the production of content, and at the end of the day this affects the production of news, of information, and the investigations that we`re working on — it’s an indirect but real impact, at the end of the day, it´s very real”.

It´s not just Aristegui. The trolls have organized time and again against prominent critical voices in Mexico. These kinds of defamation campaigns may seem softer than death threats, but they take their toll on activists and journalists. By creating a constant string of scandals, these tactics undermine their credibility and distract from the issues they work to expose.

So, what can be done?

It´s clear this problem is not going to go away. The trolls keep evolving and they´re getting around Twitter´s spam team easily. Alberto is worried about the role they will play during Mexico´s elections in 2018.

If Amnesty can identify the troll networks, then it is clear that Twitter can too. And Twitter have access to a lot more data to identify the patterns in their activity. The company can and should be doing more. It’s not just a question of investing more resources; the company also needs to localize its strategies. As a US-based company, with a large share of its income and users in English speaking markets, the Spanish-speaking platform is being neglected. The result is a troll takeover.

If Twitter doesn’t act, the work of documenting and reporting on the trolls will be left to individuals like Alberto. And that work is putting him at risk.

Alberto finishes our interview. He has to rush to another meeting, this one is with the government´s National Mechanism for the Protection of Journalists. He has just been informed of a renewal of his “protective measures” from the state because of all the death threats he receives.

“It takes a profound hope and maybe some craziness to keep working on this in Mexico and hope it will change. All my friends who keep on publishing say the same. We take the risk because we are mad enough to believe it will change.”

Just before he closes his laptop, he shows me one final thing.

“Look, see the trolls have gone into action. You can see them in real-time.”

On his computer screen, tiny flickering lines expand and connect, expanding outwards in seconds until a daunting grey cloud fills his screen, undulating and mutating as a new wave of tweets pour in.



Amnesty Global Insights
Amnesty Insights

Insights from Amnesty International on global human rights issues | business, technology, arms, death penalty, refugees & ESC rights